CVE-2013-2640: XSS
ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version than CVE-2013-0731.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2640?
CVE-2013-2640 has a medium severity rating due to its potential for unauthorized access and exploitation.
How do I fix CVE-2013-2640?
To fix CVE-2013-2640, update the MailUp plugin to version 1.3.2 or later.
What types of attacks are possible with CVE-2013-2640?
CVE-2013-2640 may allow attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks.
Which versions of the MailUp plugin are affected by CVE-2013-2640?
The affected versions of the MailUp plugin are all versions prior to 1.3.2, including 1.0.0 to 1.3.1.
Is WordPress itself vulnerable due to CVE-2013-2640?
No, WordPress itself is not vulnerable as the issue is specific to the MailUp plugin.